Recent FAQ Changes RSS

Latest changes to PCI SSC frequently asked questions.

❓ FAQ 1271 Deleted

Can I combine sections from different versions of the PA-DSS?

No. When validating payment application compliance through a Report on Validation (ROV) you may not 'combine' requirements from multiple versions of the standard — your assessment must be to one …

❓ FAQ 1602 New

Should entities with enterprise or internal service providers, used to provide internal services to other corporate entities, conduct separate PCI DSS assessments of these service providers or include them as part of each corporate entity’s PCI DSS assessment?

Assessed entities have the discretion to either have enterprise functions assessed separately as an internal service provider or include those functions in each individual corporate entity’s PCI DSS assessment. Regardless …